Cyber Insurance Application Scannermap an application to controls

Cowbell Cyber cyber policy application, held

The questions of the Cowbell Cyber Prime 250 Renewal Application, held and mapped to the ISO 27001:2022 controls, the SOC 2 criteria and the NIST CSF 2.0 outcomes each one reaches. The source document (read 2026-10-11). The date shown is the date this copy was read, not a version the form itself states. This page quotes only the question each mapped row needs and states its source; it does not publish the carrier's form. A complete form would be held only under a stated policy for copyrighted forms. Cowbell Cyber is a source document, never a customer.

This document's questions reach 55 of 290 held controls. Whether an applicant is offered cover is the carrier’s underwriting decision. 1 question here is flagged knockout (a "no" is a common decline point) and 0 flagged warranty (an answer the carrier relies on, that can affect cover if wrong).

Application question Has there been any change to the answers you provided to Cowbell in the prior-year's application for insurance?
Cowbell Cyber held application question

No held control answers this line.

Application question How often does the organization perform backups of business-critical data?
Cowbell Cyber held application question
ISO 27001:2022 A.8.13 Information backup
Evidence to have on file (guidance, our wording)
  • The topic-specific backup policy and backup plans stating scope, extent, frequency and retention per system aligned with RPO
  • Backup job monitoring reports with evidence that failed jobs were investigated and rerun
ISO 27001:2022 A.8.14 Redundancy of information processing facilities
Evidence to have on file (guidance, our wording)
  • Documented availability requirements for business services and systems
  • Architecture diagrams showing redundancy such as dual providers, redundant networks, separate data centres, redundant power and load-balanced instances
SOC 2 A1.2 Environmental protection, backup and recovery infrastructure
Evidence to have on file (guidance, our wording)
  • Backup policy defining scope, frequency and retention
  • Backup job monitoring and failure remediation records
SOC 2 A1.3 Testing recovery plan procedures
Evidence to have on file (guidance, our wording)
  • Disaster recovery or continuity test plan and results in the period
  • Backup restore test records with verification of completeness
NIST CSF 2.0 PR.DS-11 Backups of data are created, protected, maintained, and tested
Evidence to have on file (guidance, our wording)
  • Backup policy with frequency and retention
  • Backup integrity test reports
Application question Do you enforce Multi-Factor Authentication (MFA) for all employees, contractors, and partners on the following?
Cowbell Cyber held application question

Flagged knockout: the wording of this question makes a "no" a common point at which a cyber application is declined or referred.

ISO 27001:2022 A.8.5 Secure authentication
Evidence to have on file (guidance, our wording)
  • An authentication standard linking required authentication strength to information classification and system criticality
  • MFA configuration and coverage reports for critical systems, remote access and privileged access, including conditional or risk-based rules
ISO 27001:2022 A.5.17 Authentication information
Evidence to have on file (guidance, our wording)
  • Credential issuance procedure requiring identity verification before new, replacement or temporary credentials are provided
  • Evidence that initial credentials are unique, delivered over protected channels and changed at first use
SOC 2 CC6.1 Logical access security over protected information assets
Evidence to have on file (guidance, our wording)
  • Asset inventory with classification for in-scope systems
  • Identity provider configuration showing MFA and password policy
NIST CSF 2.0 PR.AA-03 Users, services, and hardware are authenticated
Evidence to have on file (guidance, our wording)
  • Multi factor authentication coverage report
  • Phishing resistant authentication rollout plan
Application question Does the organization have an incident response plan - tested and in-effect - setting forth specific action items and responsibilities for relevant parties in the event of a cyber incident or data breach matter?
Cowbell Cyber held application question
ISO 27001:2022 A.5.29 Information security during disruption
Evidence to have on file (guidance, our wording)
  • Business continuity plans that contain information security requirements and the controls, systems and tools needed during disruption
  • A documented analysis of which security controls must be adapted during disruption and how
ISO 27001:2022 A.5.30 ICT readiness for business continuity
Evidence to have on file (guidance, our wording)
  • The business impact analysis with prioritized activities, supporting ICT services and their RTOs, and RPOs for required information
  • Selected ICT continuity strategies covering before, during and after disruption
ISO 27001:2022 A.8.14 Redundancy of information processing facilities
Evidence to have on file (guidance, our wording)
  • Documented availability requirements for business services and systems
  • Architecture diagrams showing redundancy such as dual providers, redundant networks, separate data centres, redundant power and load-balanced instances
SOC 2 CC9.1 Mitigating risks of business disruption
Evidence to have on file (guidance, our wording)
  • Business continuity and disaster recovery plans covering the in-scope service
  • Business impact analysis
SOC 2 A1.2 Environmental protection, backup and recovery infrastructure
Evidence to have on file (guidance, our wording)
  • Backup policy defining scope, frequency and retention
  • Backup job monitoring and failure remediation records
NIST CSF 2.0 PR.IR-03 Mechanisms are implemented to achieve resilience requirements in normal and adverse situations
Evidence to have on file (guidance, our wording)
  • Resilience architecture patterns for critical services
  • Failover and failback tested with evidence
NIST CSF 2.0 RC.RP-01 The recovery portion of the incident response plan is executed once initiated from the incident response process
Evidence to have on file (guidance, our wording)
  • Recovery plan with triggers and decision rights
  • Execution log of recovery activities
Application question In the 12 months prior to this renewal, has the organization experienced any change in the size or scope of the organization's business, including any mergers, acquisitions, divestitures, and/or repurposing?
Cowbell Cyber held application question

This is a loss history question, not a control requirement. It reaches no held control.

No held control answers this line.

Application question Does the organization assign a person responsible for information security?
Cowbell Cyber held application question
ISO 27001:2022 A.5.1 Policies for information security
Evidence to have on file (guidance, our wording)
  • The top-level information security policy with top management approval, covering the definition, objectives or objective-setting framework, principles, commitments to requirements and continual improvement, role assignments and the exceptions procedure
  • The register of topic-specific policies with an owner, approving manager and version for each
ISO 27001:2022 A.5.2 Information security roles and responsibilities
Evidence to have on file (guidance, our wording)
  • A documented roles and responsibilities matrix covering asset protection, specific security processes, risk management and residual risk acceptance, and user duties
  • Named risk owners with evidence that they accepted residual risks
ISO 27001:2022 A.5.4 Management responsibilities
Evidence to have on file (guidance, our wording)
  • Evidence that security briefings on roles and responsibilities occur before access is granted, such as onboarding checklists tied to access provisioning
  • Role-specific guidance documents setting out security expectations
SOC 2 CC1.3 Structures, reporting lines, authorities and responsibilities (COSO principle 3)
Evidence to have on file (guidance, our wording)
  • Current organisation chart including security, IT operations, compliance and privacy functions
  • Job descriptions or RACI naming security and privacy responsibilities
SOC 2 CC5.3 Deploying controls through policies and procedures (COSO principle 12)
Evidence to have on file (guidance, our wording)
  • Approved information security policy set with owners and review dates
  • Evidence of annual policy review and approval
NIST CSF 2.0 GV.PO-01 Policy for managing cybersecurity risks is established based on organizational context, cybersecurity strategy, and priorities and is communicated and enforced
Evidence to have on file (guidance, our wording)
  • Cybersecurity risk management policy approved by leadership
  • Policy linkage matrix to standards and procedures
NIST CSF 2.0 GV.RR-01 Organizational leadership is responsible and accountable for cybersecurity risk and fosters a culture that is risk-aware, ethical, and continually improving
Evidence to have on file (guidance, our wording)
  • Board cyber accountability charter
  • Executive cyber scorecard with named owners
Application question Does the organization hold mandatory cybersecurity training with all employees at least annually?
Cowbell Cyber held application question
ISO 27001:2022 A.6.3 Information security awareness, education and training
Evidence to have on file (guidance, our wording)
  • A documented awareness, education and training programme aligned with the policies and planned by role, including external personnel
  • Completion records for initial training of new starters and role changers and for periodic refreshers
SOC 2 CC1.4 Attracting, developing and retaining competent people (COSO principle 4)
Evidence to have on file (guidance, our wording)
  • Background check policy and completed checks for a sample of new hires and contractors
  • Role competency requirements and performance review records
SOC 2 CC2.2 Internal communication of objectives and control responsibilities (COSO principle 14)
Evidence to have on file (guidance, our wording)
  • Security awareness training content and completion records
  • Published information security policies accessible to staff with change notices
NIST CSF 2.0 PR.AT-01 Personnel are provided with awareness and training so that they possess the knowledge and skills to perform general tasks with cybersecurity risks in mind
Evidence to have on file (guidance, our wording)
  • Security awareness program curriculum
  • Completion records by population
Application question Does the organization encrypt all external communications containing sensitive information?
Cowbell Cyber held application question
ISO 27001:2022 A.8.24 Use of cryptography
Evidence to have on file (guidance, our wording)
  • The topic-specific cryptography policy with approved algorithms, key lengths, protocols and usage by information classification
  • Evidence of encryption on endpoints, removable media and data in transit, aligned with the policy
ISO 27001:2022 A.5.14 Information transfer
Evidence to have on file (guidance, our wording)
  • The topic-specific information transfer policy and its communication record
  • Transfer agreements with third parties covering recipient authentication, protection levels, incident liability and labelling
SOC 2 CC6.7 Restricting and protecting information in transmission, movement and removal
Evidence to have on file (guidance, our wording)
  • TLS and encryption standards for data in transit
  • Removable media policy and technical enforcement
SOC 2 CC6.1 Logical access security over protected information assets
Evidence to have on file (guidance, our wording)
  • Asset inventory with classification for in-scope systems
  • Identity provider configuration showing MFA and password policy
NIST CSF 2.0 PR.DS-02 The confidentiality, integrity, and availability of data-in-transit are protected
Evidence to have on file (guidance, our wording)
  • TLS configuration standards and scan results
  • VPN and zero trust network access policy
NIST CSF 2.0 PR.DS-01 The confidentiality, integrity, and availability of data-at-rest are protected
Evidence to have on file (guidance, our wording)
  • Data at rest encryption inventory by store type
  • Storage configuration baselines with attestation
Application question Does the organization encrypt sensitive information stored on the cloud?
Cowbell Cyber held application question
ISO 27001:2022 A.8.24 Use of cryptography
Evidence to have on file (guidance, our wording)
  • The topic-specific cryptography policy with approved algorithms, key lengths, protocols and usage by information classification
  • Evidence of encryption on endpoints, removable media and data in transit, aligned with the policy
ISO 27001:2022 A.7.10 Storage media
Evidence to have on file (guidance, our wording)
  • The topic-specific removable media policy and evidence it was communicated to users
  • Endpoint configuration showing USB and SD ports disabled unless a business reason is approved, and monitoring of transfers to removable media
ISO 27001:2022 A.8.1 User end point devices
Evidence to have on file (guidance, our wording)
  • The topic-specific endpoint policy covering classification limits, registration, software restrictions, updates, network connection rules, encryption, malware protection, remote wipe, backup and port control
  • Device management (MDM or endpoint management) reports showing enrolment, encryption, patch level, firewall and anti-malware status
SOC 2 CC6.1 Logical access security over protected information assets
Evidence to have on file (guidance, our wording)
  • Asset inventory with classification for in-scope systems
  • Identity provider configuration showing MFA and password policy
SOC 2 CC6.7 Restricting and protecting information in transmission, movement and removal
Evidence to have on file (guidance, our wording)
  • TLS and encryption standards for data in transit
  • Removable media policy and technical enforcement
NIST CSF 2.0 PR.DS-01 The confidentiality, integrity, and availability of data-at-rest are protected
Evidence to have on file (guidance, our wording)
  • Data at rest encryption inventory by store type
  • Storage configuration baselines with attestation
NIST CSF 2.0 PR.DS-02 The confidentiality, integrity, and availability of data-in-transit are protected
Evidence to have on file (guidance, our wording)
  • TLS configuration standards and scan results
  • VPN and zero trust network access policy
Application question How often does the organization apply updates to critical IT-systems and applications ("security patching"?
Cowbell Cyber held application question
ISO 27001:2022 A.8.8 Management of technical vulnerabilities
Evidence to have on file (guidance, our wording)
  • A software asset inventory with vendor, product, version, deployment location and responsible owner
  • Defined vulnerability management roles and a list of monitored vulnerability information sources
ISO 27001:2022 A.8.19 Installation of software on operational systems
Evidence to have on file (guidance, our wording)
  • Procedures for installing and updating operational software, including authorization, testing and rollback planning
  • Change and deployment records showing management authorization, successful testing and the administrator who performed the installation
ISO 27001:2022 A.8.29 Security testing in development and acceptance
Evidence to have on file (guidance, our wording)
  • Security test plans with schedules, inputs, expected outputs, evaluation criteria and decisions, scaled to the system's importance and change impact
  • Security test results covering authentication, access restriction, cryptography, secure coding and configuration
SOC 2 CC7.1 Detecting configuration changes and new vulnerabilities
Evidence to have on file (guidance, our wording)
  • Hardening standards or benchmarks for in-scope platforms
  • Configuration compliance scan results
NIST CSF 2.0 ID.RA-01 Vulnerabilities in assets are identified, validated, and recorded
Evidence to have on file (guidance, our wording)
  • Vulnerability scanning coverage report
  • Vulnerability triage workflow with severity SLAs
NIST CSF 2.0 PR.PS-02 Software is maintained, replaced, and removed commensurate with risk
Evidence to have on file (guidance, our wording)
  • Software lifecycle policy with end of support tracking
  • Patch management cadence and exception register
Application question Has the organization filed any claims due to a cyber event in last five years?
Cowbell Cyber held application question

This is a loss history question, not a control requirement. It reaches no held control.

No held control answers this line.

Application question Civil or criminal action or administrative proceeding alleging violation of any federal, state, local or common law?
Cowbell Cyber held application question

This is a loss history question, not a control requirement. It reaches no held control.

No held control answers this line.

Application question Is there currently any pending litigation, administrative proceeding or claim against the named applicant, organization and/or any of the prospective insureds?
Cowbell Cyber held application question

This is a loss history question, not a control requirement. It reaches no held control.

No held control answers this line.

Application question During the last three years, has the organization suffered loss of business income as a result of unscheduled system downtime?
Cowbell Cyber held application question

This is a loss history question, not a control requirement. It reaches no held control.

No held control answers this line.

Application question During the last three years, has the organization suffered a security breach requiring customer or third-party notification according to state or federal regulations?
Cowbell Cyber held application question

This is a loss history question, not a control requirement. It reaches no held control.

No held control answers this line.

Application question Does the organization verify vendor/supplier bank accounts before adding to their accounts payable systems?
Cowbell Cyber held application question
ISO 27001:2022 A.5.19 Information security in supplier relationships
Evidence to have on file (guidance, our wording)
  • The topic-specific supplier relationship policy and its communication record
  • A supplier inventory categorized by type and by the information, services and infrastructure each can access
ISO 27001:2022 A.5.20 Addressing information security within supplier agreements
Evidence to have on file (guidance, our wording)
  • Supplier agreements containing security clauses proportionate to the relationship, such as classification mapping, agreed controls, incident notification, subcontracting, right to audit and termination terms
  • A register of contracts, memoranda and information-sharing arrangements with outside parties showing what information each covers and when it was last reviewed
ISO 27001:2022 A.5.21 Managing information security in the information and communication technology (ICT) supply chain
Evidence to have on file (guidance, our wording)
  • Security requirements included in ICT acquisition specifications and contracts, including flow-down to sub-suppliers
  • Software component information such as SBOMs and descriptions of security functions and secure configuration obtained from product suppliers
SOC 2 CC9.2 Assessing and managing vendor and business partner risk
Evidence to have on file (guidance, our wording)
  • Vendor inventory with risk tiers and the review frequency set for each tier
  • Due diligence records, for example vendor SOC reports reviewed with complementary controls noted
SOC 2 P6.4 Privacy commitments from vendors and third parties
Evidence to have on file (guidance, our wording)
  • Data processing agreements with privacy clauses
  • Periodic assessments of vendors' privacy compliance
NIST CSF 2.0 GV.SC-01 A cybersecurity supply chain risk management program, strategy, objectives, policies, and processes are established and agreed to by organizational stakeholders
Evidence to have on file (guidance, our wording)
  • Third party risk management program charter
  • Supplier risk policy with tiering criteria
NIST CSF 2.0 GV.SC-05 Requirements to address cybersecurity risks in supply chains are established, prioritized, and integrated into contracts and other types of agreements with suppliers and other relevant third parties
Evidence to have on file (guidance, our wording)
  • Standard supplier security requirements catalog
  • Contract clause library with cyber obligations
Application question Does the organization authenticate funds transfer requests (e.g. by calling a customer to verify the request at a predetermined phone number?
Cowbell Cyber held application question
ISO 27001:2022 A.5.3 Segregation of duties
Evidence to have on file (guidance, our wording)
  • the bank or treasury platform dual-authorisation setup and the payment approval workflow, showing a second approver on a different device above the threshold
  • the callback or out-of-band verification procedure for a change to payee bank details, with a dated example
ISO 27001:2022 A.6.3 Information security awareness, education and training
Evidence to have on file (guidance, our wording)
  • A documented awareness, education and training programme aligned with the policies and planned by role, including external personnel
  • Completion records for initial training of new starters and role changers and for periodic refreshers
ISO 27001:2022 A.8.5 Secure authentication
Evidence to have on file (guidance, our wording)
  • An authentication standard linking required authentication strength to information classification and system criticality
  • MFA configuration and coverage reports for critical systems, remote access and privileged access, including conditional or risk-based rules
SOC 2 CC6.3 Role-based access, least privilege and segregation of duties
Evidence to have on file (guidance, our wording)
  • the bank or treasury platform dual-authorisation setup and the payment approval workflow, showing a second approver on a different device above the threshold
  • the callback or out-of-band verification procedure for a change to payee bank details, with a dated example
SOC 2 CC3.3 Considering fraud risk (COSO principle 8)
Evidence to have on file (guidance, our wording)
  • Fraud risk assessment or fraud section of the enterprise risk assessment
  • Analysis of privileged access and data misuse scenarios
NIST CSF 2.0 PR.AA-05 Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties
Evidence to have on file (guidance, our wording)
  • Access policy framework with role definitions
  • Privileged access management deployment evidence
Application question Does the organization prevent unauthorized employees from initiating wire transfers?
Cowbell Cyber held application question
ISO 27001:2022 A.5.3 Segregation of duties
Evidence to have on file (guidance, our wording)
  • the bank or treasury platform dual-authorisation setup and the payment approval workflow, showing a second approver on a different device above the threshold
  • the callback or out-of-band verification procedure for a change to payee bank details, with a dated example
ISO 27001:2022 A.6.3 Information security awareness, education and training
Evidence to have on file (guidance, our wording)
  • A documented awareness, education and training programme aligned with the policies and planned by role, including external personnel
  • Completion records for initial training of new starters and role changers and for periodic refreshers
ISO 27001:2022 A.8.5 Secure authentication
Evidence to have on file (guidance, our wording)
  • An authentication standard linking required authentication strength to information classification and system criticality
  • MFA configuration and coverage reports for critical systems, remote access and privileged access, including conditional or risk-based rules
SOC 2 CC6.3 Role-based access, least privilege and segregation of duties
Evidence to have on file (guidance, our wording)
  • the bank or treasury platform dual-authorisation setup and the payment approval workflow, showing a second approver on a different device above the threshold
  • the callback or out-of-band verification procedure for a change to payee bank details, with a dated example
SOC 2 CC3.3 Considering fraud risk (COSO principle 8)
Evidence to have on file (guidance, our wording)
  • Fraud risk assessment or fraud section of the enterprise risk assessment
  • Analysis of privileged access and data misuse scenarios
NIST CSF 2.0 PR.AA-05 Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties
Evidence to have on file (guidance, our wording)
  • Access policy framework with role definitions
  • Privileged access management deployment evidence
Application question Are all internet-accessible systems (e.g. web-, email-servers) segregated from the organization's trusted network (e.g. within a demilitarized zone (DMZ) or at a third-party service provider?
Cowbell Cyber held application question
ISO 27001:2022 A.8.20 Networks security
Evidence to have on file (guidance, our wording)
  • Current network diagrams and device configuration backups for routers, switches, firewalls and wireless controllers
  • Defined responsibilities and procedures for network device management, separated from system operations where appropriate
ISO 27001:2022 A.8.21 Security of network services
Evidence to have on file (guidance, our wording)
  • Service agreements with internal and external network providers specifying security features, service levels and requirements
  • Right-to-audit clauses and third-party attestations from network and managed security service providers, with records of review
ISO 27001:2022 A.8.22 Segregation of networks
Evidence to have on file (guidance, our wording)
  • Network segmentation design defining domains by trust, criticality, sensitivity or organizational unit, with the assessment that justified it
  • Firewall or filtering router rules controlling traffic between domains, with rule review records
SOC 2 CC6.6 Protection against threats from outside the system boundary
Evidence to have on file (guidance, our wording)
  • Firewall and security group rule sets with review evidence
  • MFA enforced on VPN, remote and administrative access
SOC 2 CC9.2 Assessing and managing vendor and business partner risk
Evidence to have on file (guidance, our wording)
  • Vendor inventory with risk tiers and the review frequency set for each tier
  • Due diligence records, for example vendor SOC reports reviewed with complementary controls noted
NIST CSF 2.0 PR.IR-01 Networks and environments are protected from unauthorized logical access and usage
Evidence to have on file (guidance, our wording)
  • Network segmentation design with zones and trust levels
  • Firewall and access control list governance
NIST CSF 2.0 DE.CM-01 Networks and network services are monitored to find potentially adverse events
Evidence to have on file (guidance, our wording)
  • Network flow telemetry coverage map by segment
  • IDS or NDR sensor inventory with placement diagram
Application question Do agreements with third-party service providers require levels of security commensurate with the organization's information security standard?
Cowbell Cyber held application question
ISO 27001:2022 A.5.19 Information security in supplier relationships
Evidence to have on file (guidance, our wording)
  • The topic-specific supplier relationship policy and its communication record
  • A supplier inventory categorized by type and by the information, services and infrastructure each can access
ISO 27001:2022 A.5.20 Addressing information security within supplier agreements
Evidence to have on file (guidance, our wording)
  • Supplier agreements containing security clauses proportionate to the relationship, such as classification mapping, agreed controls, incident notification, subcontracting, right to audit and termination terms
  • A register of contracts, memoranda and information-sharing arrangements with outside parties showing what information each covers and when it was last reviewed
ISO 27001:2022 A.5.21 Managing information security in the information and communication technology (ICT) supply chain
Evidence to have on file (guidance, our wording)
  • Security requirements included in ICT acquisition specifications and contracts, including flow-down to sub-suppliers
  • Software component information such as SBOMs and descriptions of security functions and secure configuration obtained from product suppliers
SOC 2 CC9.2 Assessing and managing vendor and business partner risk
Evidence to have on file (guidance, our wording)
  • Vendor inventory with risk tiers and the review frequency set for each tier
  • Due diligence records, for example vendor SOC reports reviewed with complementary controls noted
SOC 2 P6.4 Privacy commitments from vendors and third parties
Evidence to have on file (guidance, our wording)
  • Data processing agreements with privacy clauses
  • Periodic assessments of vendors' privacy compliance
NIST CSF 2.0 GV.SC-01 A cybersecurity supply chain risk management program, strategy, objectives, policies, and processes are established and agreed to by organizational stakeholders
Evidence to have on file (guidance, our wording)
  • Third party risk management program charter
  • Supplier risk policy with tiering criteria
NIST CSF 2.0 GV.SC-05 Requirements to address cybersecurity risks in supply chains are established, prioritized, and integrated into contracts and other types of agreements with suppliers and other relevant third parties
Evidence to have on file (guidance, our wording)
  • Standard supplier security requirements catalog
  • Contract clause library with cyber obligations
Application question Has the organization tested a full failover of the most critical servers?
Cowbell Cyber held application question
ISO 27001:2022 A.5.29 Information security during disruption
Evidence to have on file (guidance, our wording)
  • Business continuity plans that contain information security requirements and the controls, systems and tools needed during disruption
  • A documented analysis of which security controls must be adapted during disruption and how
ISO 27001:2022 A.5.30 ICT readiness for business continuity
Evidence to have on file (guidance, our wording)
  • The business impact analysis with prioritized activities, supporting ICT services and their RTOs, and RPOs for required information
  • Selected ICT continuity strategies covering before, during and after disruption
ISO 27001:2022 A.8.14 Redundancy of information processing facilities
Evidence to have on file (guidance, our wording)
  • Documented availability requirements for business services and systems
  • Architecture diagrams showing redundancy such as dual providers, redundant networks, separate data centres, redundant power and load-balanced instances
SOC 2 CC9.1 Mitigating risks of business disruption
Evidence to have on file (guidance, our wording)
  • Business continuity and disaster recovery plans covering the in-scope service
  • Business impact analysis
SOC 2 A1.2 Environmental protection, backup and recovery infrastructure
Evidence to have on file (guidance, our wording)
  • Backup policy defining scope, frequency and retention
  • Backup job monitoring and failure remediation records
NIST CSF 2.0 PR.IR-03 Mechanisms are implemented to achieve resilience requirements in normal and adverse situations
Evidence to have on file (guidance, our wording)
  • Resilience architecture patterns for critical services
  • Failover and failback tested with evidence
NIST CSF 2.0 RC.RP-01 The recovery portion of the incident response plan is executed once initiated from the incident response process
Evidence to have on file (guidance, our wording)
  • Recovery plan with triggers and decision rights
  • Execution log of recovery activities

Controls not asked in this held document (235)

None of this held document's questions reach 235 of the 290 held controls (for example A.5.5, A.5.6, A.5.7, A.5.8, A.5.9, A.5.10, A.5.11, A.5.12). That is a fact about this held document, not about what the carrier underwrites on: a carrier's fuller forms and supplements ask controls this summary does not, multi-factor authentication, offline backups and patching among them. A control here is not asserted as required, and not asserted as not required.